Tor History: From Onion Routing to Today
Tor start for 1995 inside U.S. Navy research lab. See the dated milestones, how onion routing work, and the straight answer on who dey fund the network.
Tor history, for short
Tor history start for 1995 for U.S. Naval Research Laboratory, wey be research lab of U.S. Navy. David Goldschlag, Michael G. Reed and Paul Syverson build the first onion routing prototypes there. The Tor Project own timeline talk about the question wey dem ask: whether “there was a way to create internet connections that don't reveal who is talking to whom”. The network wey people dey use today launch for October 2002, and dem release the code under free and open software license. Tor Project, Inc. start as nonprofit for 2006.
Every date wey dey below come from Tor Project published timeline, its release notes, or its own support pages. If people dey contest any claim, like who dey fund the work, this section go state wetin the evidence show and where you fit check am yourself.
Wetin onion routing really dey do
Onion routing dey separate two facts wey internet normally dey keep together: who you be, and wetin you ask for. Your Tor client dey pick three relays and build circuit through dem. E dey wrap your traffic with three layers of encryption, one layer for each relay. Each relay dey remove one layer, learn only the address of the next hop, then pass the packet go front. Na this layering make dem call am onion routing.
The first relay, wey dem dey call guard, dey see your IP address but e no dey see your destination. The last relay, wey be exit, dey see your destination but e no dey see your IP address. The middle relay no dey see either one. No single relay get both sides, and na this be the whole security argument. Na why unrelated people suppose operate the relays. If one organisation run your guard and your exit, the separation don disappear and the encryption no give you any protection.
The known weakness na traffic correlation. Observer wey fit monitor both ends of a circuit at the same time fit match the timing and packet sizes wey dey enter with the ones wey dey come out. Tor no dey protect against attacker wey fit monitor the whole internet at once. The 2004 design paper by Roger Dingledine, Nick Mathewson and Paul Syverson, "Tor: The Second-Generation Onion Router", talk this one for the threat model.
Why private network for no go useful
Na here short summaries dey skip, and na here explain everything else for this page.
Military or intelligence organisation no fit get anonymity from network wey dey carry only its own traffic. Anonymity na property of crowd, e no be property of cipher. If every connection wey dey comot from the network belong to one office, observer wey see connection comot don already know the answer. The encryption still dey work perfectly. But anonymity no dey exist, because nobody dey there to confuse observer.
So, the design suppose public, and dem suppose mix the traffic with other people traffic. The code come out under free software licence for October 2002, and anybody fit run relay. Journalists, activists, researchers, and ordinary people wey dey avoid advertising network all become the crowd wey dey protect everybody else inside am. Dingledine and Mathewson explain this argument for 2006 inside paper wey dem call "Anonymity Loves Company: Usability and the Network Effect", presented for Workshop on the Economics of Information Security. The conclusion be say size and variety of the user base na security property of the system. E no be marketing number.
From alpha code to nonprofit
The Tor Project timeline and the papers wey dem publish record these steps:
- October 2002: dem deploy the Tor network, with the code "under a free and open software license".
- End of 2003: the network dey run for "about a dozen volunteer nodes, mostly in the U.S., plus one in Germany".
- 2004: Dingledine, Mathewson and Syverson publish the design paper "Tor: The Second-Generation Onion Router".
- 2004: the Electronic Frontier Foundation (EFF) start to fund the work on Tor.
- 2006: dem establish The Tor Project, Inc. as 501(c)(3) nonprofit to maintain development.
- 2007: work start on bridges, because national firewalls don start block the public relay list.
- 2008: development of Tor Browser start.
Two later dates matter for how people dey use the network now. The Tor Project timeline put Tor use during the Arab Spring for late 2010, to protect identity and reach blocked sites. E also record the 2013 Snowden documents as the time when people widely understand Tor role, and e talk say the documents show Tor never break for that time. Neither event change the protocol. Both events change who install am.
Who dey pay for Tor, and how you fit check am
The Tor Project answer this for its own support pages: "The Tor Project dey get support from a mix of government grants, private foundations, and individual donors." Government money dey part of am, and e don dey so from the beginning. The supporters page name the U.S. Department of State together with Ford Foundation, Open Technology Fund, Craig Newmark Philanthropies, and companies like Brave, DuckDuckGo, Mullvad VPN and Fastly. Dem publish audited financials as blog posts, with the latest one covering the 2023 to 2024 financial year for December 2025. The project position be say "talking openly about our sponsors and funding model is the best way to maintain trust with our community".
The useful question no be who pay. Na wetin money fit buy. Tor no be service wey you log into. Na protocol specification, client wey you fit read the source code, and network of relays wey strangers dey operate. Person wey wan put backdoor go need put am for one of three places, and you fit check each one.
- For the source. The client na open source, and dem specify the protocol publicly. Academic researchers dey publish attacks on Tor regularly, and dem get every professional reason to find flaw before anybody else.
- For the binary. Tor Browser builds don dey deterministic since August 2013, so independent builder fit rebuild release and compare am byte for byte with the published download. If binary no match the source, you fit see am without trusting the person wey release am.
- For the relays. The Tor Project no dey run the network. "The Tor network relies on volunteers to donate bandwidth", and guards, middle relays, exits and bridges belong to thousands of operators wey no relate to each other. If person compromise one funder, e no mean say dem compromise the relay operators.
The project's own statement short: "Tor has no backdoors. The software is open source, its code can be independently audited, and every release is signed to protect against tampering." That sentence only get value because each part point to something wey you fit go verify.
Real caveat dey, and e concern priorities instead of integrity. Grant money dey decide which work go happen first, so dem don fund censorship circumvention more consistently than things like network performance. That na fair criticism of the project. E different from saying "the code is compromised", and you answer am by reading the financial reports instead of trusting anybody assurance.
Hidden services don become onion services
Onion service na server wey no ever reveal its IP address. The client and server each build their own circuit go one meeting point inside the network, so neither side go learn the other side address. The address no be name wey any registry assign to anybody. E derive from the server public key, na why .onion address dey look like random characters.
The onion services timeline show the releases:
- 8 April 2004: dem first implement hidden services for Tor 0.0.6pre1.
- 21 September 2007: version 2 hidden services arrive for Tor 0.2.0.7-alpha.
- 19 December 2016: version 3 development start for Tor 0.3.0.1-alpha.
- 9 January 2018: version 3 release for Tor 0.3.2.9.
The rename from "hidden services" to "onion services" happen gradually, no be for one particular date, and Tor Project own documentation still use both words. The old word describe the wrong thing. Plenty onion sites dey public, indexed, and advertised; na the server location dey hidden, no be the site. The original name still dey inside the config file, and e be useful fossil. Na still so you declare one for torrc:
HiddenServiceDir /var/lib/tor/my_service/
HiddenServicePort 80 127.0.0.1:8080The directory hold the service keys and one hostname file wey contain the address. The port line map one port for the onion address to one local address for the same machine, so the web server fit remain bound to 127.0.0.1 and never listen on any public interface. Version 3 na the default, so any service wey you create with these two lines today go get v3 address.
Onion address no be domain name too. RFC 7686, wey dem publish for October 2015, reserve .onion as special-use domain name so ordinary resolvers go stop leaking these lookups into public DNS (domain name system). The rule wey e set clear: "Authoritative servers MUST respond to queries for .onion with NXDOMAIN." Compare am with how ordinary domain name dey get resolved and you go see the main difference. Registry assign DNS name to you, then servers wey you no control go look am up. Onion address na public key, so e authenticate itself and no lookup dey needed.
Why old .onion addresses stop working
The two address formats no compatible, and dem don switch off the old one permanently.
The data behind this chart
[
{
"version": "v2 (retired 2021)",
"address_length_chars": 16,
"service_key": "RSA-1024",
"address_hash": "SHA-1, truncated to 80 bits"
},
{
"version": "v3 (current)",
"address_length_chars": 56,
"service_key": "Ed25519",
"address_hash": "SHA3-256"
}
]A v2 address be 16 characters because e carry only the first 80 bits of a SHA-1 hash from an RSA-1024 public key. A v3 address be 56 characters because e carry complete Ed25519 public key, plus checksum and version byte. The v3 address long because e no dey truncate the key again. So, the address itself don become the complete identity of the service.
The deprecation follow announced schedule:
- 15 September 2020, Tor 0.4.4.x: Tor start warn operators and clients say v2 don deprecate.
- 15 July 2021, Tor 0.4.6.x: Tor remove v2 support from the code base.
- 15 October 2021: new stable client releases for every supported series disable v2.
The reason wey dem give na cryptographic. "As humankind's understanding of math and cryptography evolved, the foundation of version 2 became fragile and at this point in time, unsafe." An 80-bit truncated SHA-1 hash and 1024-bit RSA key both dey below sensible security level by 2021, and the address format no get space to change either one.
The result for reader simple, so e good make we talk am plainly. Every 16 character .onion link wey dem publish before 2021 don die permanently, and no redirect dey. You no fit upgrade v2 address because the address na the old key. Operators need create new service and publish the new address through channel wey their users already trust.
Bridges and pluggable transports: censorship dey move go front
Dem publish list of public relays deliberately, so client fit choose im own path instead of trusting one server to choose am. That same published list na ready-made blocklist for any country wey want stop Tor. Work on bridges start for 2007. Bridge na relay wey no dey inside public list. You fit request small number of dem through web or email, and censor no fit block addresses wey e no fit enumerate.
Blocking later move from addresses go traffic shape. Deep packet inspection fit recognise Tor protocol for network traffic, no matter which IP address e dey go. The answer na pluggable transports: wrapper wey change how Tor traffic dey look without changing wetin e dey do. For current Tor Browser, dem dey ship as one binary wey dem call lyrebird, wey replace obfs4proxy, and client side na three lines of torrc:
UseBridges 1
ClientTransportPlugin meek_lite,obfs4,snowflake,webtunnel exec [PATH]/lyrebird
Bridge obfs4 <IP ADDRESS>:<PORT> <FINGERPRINT> cert=<CERTIFICATE> iat-mode=0Replace [PATH] with directory wey hold lyrebird binary, and copy the complete Bridge line from Tor Project's bridges site instead of typing am. Each transport dey solve different blocking method:
- obfs4 make the traffic look like nothing wey filter fit recognise, with no protocol header wey filter fit match. Tor own advice na make you try am first, because na randomising transport wey dey work for most people.
- snowflake send you through short-lived proxies wey volunteers dey run inside ordinary web browsers, so address wey you connect to dey change. E reach stable Tor Browser for version 10.5 on 6 July 2021.
- meek route the connection through large cloud provider, so the traffic go look like say e dey go that provider. To block am mean say dem must block the provider too.
- webtunnel take opposite approach to obfs4. Instead of looking like nothing, e look like ordinary HTTPS connection to web server, by "wrapping the payload connection into a WebSocket-like HTTPS connection". Tor Project release am for stable Tor Browser on 12 March 2024, for networks wey permit only short list of protocols.
That sequence show the real shape of the last twenty years. Each new transport dey exist because specific blocking technique start to work, and the release dates record wetin censors dey do that year.
Tor no be VPN, and VPS no be either one
Many people dey come to Tor after dem don read about VPNs, so e good make we talk am exact. A VPN (virtual private network) dey send your traffic go one server wey one company dey run, and that company dey see your real address and your destination for the same time. Tor dey send your traffic through three relays wey different people dey run, so no single one of dem get both information. These na different trust models with different ways dem fit fail. The difference between a VPS and a VPN explain where each one belong.
If wetin you want na private tunnel between machines wey you control, instead of anonymity inside crowd, then na VPN wey you run yourself you need. You fit self-host a WireGuard VPN on a VPS with about forty lines of config. That one protect your traffic from the local network and your internet provider. E no give you anonymity from the company wey dey host the server, because you rent that server with your own payment details. The separate question of whether VPS hosting is safe concern another threat: who else fit reach your box.
To run a relay na the other direction, and the network depend on am. Bridges, guards, middle relays and exits all need operators, and Tor Project relay guide make am clear say "running a relay requires technical skill and commitment". Exits get legal risk, because other people's traffic dey leave the internet under your IP address, and your hosting provider go hear about am. Read that guide before you start one, no be after.
FAQ
Tor na US government build am?
Onion routing start for U.S. Naval Research Laboratory for 1995, where David Goldschlag, Michael G. Reed and Paul Syverson build the first prototypes. Tor itself na the next-generation design, wey Roger Dingledine, Nick Mathewson and Paul Syverson start around 2001 and 2002, and dem deploy the network for October 2002 under free software licence. The Tor Project, Inc. don be independent 501(c)(3) nonprofit since 2006. The government origin na real, and na also the reason dem open the network to everybody: network wey dey carry one organisation traffic no fit give that organisation anonymity, because every connection wey comot from there identify the sender through the fact say e dey use am.
Government funding mean say Tor get backdoor?
The Tor Project answer be: "Tor get no backdoors. The software na open source, independent people fit audit the code, and every release get signature to protect am against tampering." Wetin make person fit test this instead of just trust promise na the structure around am. Dem specify the protocol publicly, Tor Browser builds dey deterministic so independent builder fit rebuild release and compare am with the published binary, and volunteers dey operate the relays instead of any funder. Funding fit influence which work dem do first, and the audited financial reports for the Tor blog show where the money come from. This na question about priorities, no be question about the code.
Why my old .onion address stop working?
Na version 2 address, and dem retire v2 onion services for 2021. Tor begin warn about am on 15 September 2020, remove v2 from the code base for Tor 0.4.6.x on 15 July 2021, and disable am for stable releases on 15 October 2021. V2 address get 16 characters before .onion and v3 address get 56. No redirect or upgrade path dey, because dem derive the address from the old cryptographic key. So the operator need create new service and publish the new address.
Tor na the same thing as VPN?
No. VPN dey send your traffic go one server wey one company operate, and that company fit see your real IP address together with your destination. Tor dey send traffic through three relays wey different people operate, so the first relay see your address without your destination, while the last relay see your destination without your address. Tor slow pass, and dem build am for anonymity against observer wey no dey monitor the whole internet. VPN fast pass, and dem build am for privacy from your local network and internet provider.
Wetin be pluggable transport, and I need one?
Pluggable transport na wrapper wey change how Tor traffic dey look for the wire without changing how Tor dey work. This stop filter wey recognise Tor protocol from matching the traffic. You need one only if plain Tor no fit connect, and this usually mean say your network or country dey block am. Tor Browser ship obfs4, snowflake, meek and webtunnel inside one binary wey dem call lyrebird. Start with obfs4, because na randomising transport wey work for most people. If that connection no complete, try webtunnel or snowflake.